Skip to main content

Security

Centrifuge security highlights:

  • 24 security reviews to date for the Centrifuge protocol, including tier-1 audit firms Spearbit and Blackthorn.
  • Launched on mainnet in 2019, 0 exploits.
  • $250,000 bug bounty program live.

The protocol codebase is fully immutable, and any emergency functions are locked behind a 48-hour timelock.

Security reviews

Protocol

AuditorScopeDateEngagementReport
SherlockV3.1Feb 2026Deployment verificationReport
yAuditV3.1Jan 2026Security reviewReport
Sherlock, BlackthornV3.1Nov-Dec 2025Audit competitionReport
xmxanuelV3.1Dec 2025Security reviewReport
yAuditV3.1Oct 2025Security reviewReport
BurraSecV3.1Oct 2025Security reviewReport
BurraSecV3.1Sep 2025Security reviewReport
BurraSecLayerZero adapterAug 2025Security reviewReport
SpearbitV3.0July 2025Security reviewReport
xmxanuelV3.0May-July 2025Security reviewReport
MacroMerkle Proof ManagerJune 2025Security reviewReport
yAuditSpoke/VaultsJune 2025Security reviewReport
SpearbitV3.0May 2025Security reviewReport
BurraSecGatewayMay 2025Security reviewReport
Alex the EntreprenerdV3.0Apr 2025Review + invariant testingReport
BurraSecGatewayApr 2025Security reviewPart 1 Part 2
xmxanuelV3.0Mar 2025Security reviewReport
SpearbitV2.1Feb 2025Security reviewReport
ReconV2.0Jan 2025Invariant testingReport
SpearbitV2.0July 2024Security reviewReport
SpearbitMorpho integrationJune 2024Security reviewReport
Alex the EntreprenerdV2.0Mar - Apr 2024Review + invariant testingPart 1 Part 2
SpearbitV1.0Oct 2023Security reviewReport
Code4renaV1.0Sep 2023Audit competitionReport
SRLabsV1.0Sep 2023Security reviewReport

Operational securitiy

The core team contributing to Centrifuge has completed an operational security review with OPSEK.

Bug bounty

Centrifuge runs an active bug bounty program with a $250,000 maximum reward, available on Cantina.

Guardian

The protocol is controlled by the Root contract, which has access on all other contracts. The Root contract enforces a 48-hour delay for any upgrades and configuration changes.

Each deployment has a Guardian role, who is authorized on the Root contract. The Guardian can pause in emergencies, schedule upgrades, and set up adapters to new networks.

Every transaction is verified by third-party signers from Cantina.

NetworkGuardian
Ethereum Mainnet0xCEb7eD5d5B3bAD3088f6A1697738B60d829635c6
Base0xCEb7eD5d5B3bAD3088f6A1697738B60d829635c6
Arbitrum0xCEb7eD5d5B3bAD3088f6A1697738B60d829635c6
Plume0xCEb7eD5d5B3bAD3088f6A1697738B60d829635c6
Avalanche0xCEb7eD5d5B3bAD3088f6A1697738B60d829635c6
BNB Smart Chain0xCEb7eD5d5B3bAD3088f6A1697738B60d829635c6